External risk intelligence

Microsoft 365 Word Copilot Command Injection Information Disclosure.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-59252

Microsoft 365 Word Copilot is a productivity tool integrated into a client-side application (Word). It operates within the user's local environment and document context rather than functioning as a public-facing network service, edge gateway, or internet-accessible appliance. Consequently, it lacks a public-facing attack surface.

Command Injection

Microsoft 365 Word Copilot

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Copilot, a technology integrated into Microsoft 365 Word. The issue could allow an attacker to potentially disclose sensitive information over a network. The main concern is confirming if this technology is in use within our environment and, if so, determining the extent of any exposure.

  • Command injection flaw in Copilot.
  • Could expose sensitive information remotely.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted commands to the Copilot feature within Microsoft 365 Word. This could lead to the disclosure of sensitive information over the network, potentially affecting other network segments.

  • No authentication required.
  • Specially crafted commands trigger vulnerability.
  • Information disclosure over network.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Copilot could allow an unauthorized attacker to gain unauthorized access to sensitive information over a network. When supported by the advisory, this could affect system data and potentially sensitive information by disclosing it to an attacker.

  • System data and sensitive information.
  • Attacker discloses information over a network.
  • Unauthorized information disclosure.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Microsoft 365 Word Copilot requires coordination between application owners and infrastructure teams to identify and assess affected systems. The first practical step is to locate all instances of Copilot, determine their network exposure and business criticality, and then identify the specific system or application owners. Remediation planning should then proceed based on this risk assessment.

  • Application and infrastructure teams own resolution.
  • Verify Copilot reachability and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Microsoft 365 Word Copilot?

Microsoft 365 Word Copilot is an AI-powered assistant embedded within the Word application. It facilitates document drafting and content analysis, operating locally within the user's document environment rather than as a public-facing network service.

What is the nature of CVE-2025-59252?

This vulnerability is classified as CWE-77, representing an improper neutralization of special elements in a command, commonly known as command injection. It allows unauthorized parties to trigger information disclosure.

How does the command injection trigger occur?

The flaw is triggered by sending specially crafted commands to the Copilot feature. The vulnerability does not require authentication and is not limited to the local client, as it can result in sensitive information being disclosed over a network.

Is this vulnerability relevant to our environment?

According to the Halo Surface Signal, this exploit is very unlikely because Copilot lacks a public-facing attack surface. As a client-side productivity tool, it is not an internet-accessible appliance or edge gateway.

How should teams respond to this vulnerability?

Teams should identify all instances of Copilot to assess network exposure and business criticality. Owners must coordinate between application and infrastructure groups to perform risk-based remediation planning.

References